Directory Traversal Security Vulnerability

Description
Directory Traversal is a vulnerability which allows attackers to access restricted directories and execute commands outside of the web server's root directory.

Impact
By exploiting directory traversal vulnerabilities, attackers step out of the root directory and access files in other directories, like sensitive system files. As a result, attackers might view restricted files or execute commands, leading to a full compromise of the Web server.

References
Acunetix Directory Traversal Attacks
Security Focus - Penetration Testing for Web Applications (Part Two)

Acunetix Web Application Security Blog

Latest Article

Web Server Security and Database Server Security

Latest Whitepaper

Why File Upload Forms are a major security threat

Testimonials

“The issues detected were of major impact; if hackers would have found the security holes, they could have hacked an entire Joomla! Site.”

Robin Muilvijk
Quality & Testing Team, Joomla!